Check Those Passwords

Microsoft has had their online password checking utility available for some time now.
At least my password(s) register as "best." 
password_checker1 
Better than nothing.  But then again, I know there are more thorough password checking utilities
out there.

Print | posted @ Tuesday, March 11, 2008 11:36 AM

Comments on this entry:

Gravatar # re: Check Those Passwords
by Morgan K Freeberg at 3/16/2008 4:23 PM

Not sure I agree with the logic. It seems to be unreasonably biased in favor of the enpasflt criteria requiring length of 8, 1 num, 1 special, mix of upper & lower alpha. If you leave everything else in but drop the special character, the resulting strength will remain weak-to-medium even though you make that puppy EXTRA long.

A dictionary-based attack is not within the realm of consideration for something like that, and the computational cycles required for a plausible brute-force attack increase by a factor of 62 for every character added. So, no, I don't think a seventy-five-character pass phrase is "medium" when an eight-character password is "strong," just because the shorter one has a percent sign.

But as you say, it's better than nothing.
  
Gravatar # re: Check Those Passwords
by Braden at 3/16/2008 8:00 PM

You got that right, Morgan :)
  
Comments have been closed on this topic.